cli-tools

Warn

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/lib/path_check.sh modifies shell profile files such as .bashrc, .zshrc, and .profile to append PATH exports and shell initialization hooks, which functions as a persistence mechanism for environment configuration.
  • [COMMAND_EXECUTION]: Several scripts, including scripts/auto_update.sh and scripts/installers/package_manager.sh, utilize sudo to perform administrative tasks like system-wide package updates and writing to protected directories like /usr/local/bin.
  • [EXTERNAL_DOWNLOADS]: The skill downloads and installs binaries, archives, and scripts from remote sources including GitHub, GitLab, and vendor-specific domains like HashiCorp and GetComposer during tool setup and updates.
  • [COMMAND_EXECUTION]: The scripts/installers/package_manager.sh script employs bash -c to execute version-check commands defined within JSON catalog files, constituting dynamic execution of shell logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 1, 2026, 04:07 AM